TINKYWINKEY KEYLOGGER
Sept. 1, 2025, 10:33 a.m.
Description
TinkyWinkey is a sophisticated Windows-based keylogger that combines persistent service execution, low-level keyboard hooks, and comprehensive system profiling. It captures all keystrokes, including special keys and multi-language input, alongside detailed system metrics such as CPU, memory, OS version, and network identifiers. The malware uses DLL injection into trusted processes and service-based persistence for stealth. It creates a log file in the user's temp directory, recording system reconnaissance details and user activity data. First observed in June 2025, TinkyWinkey exemplifies the evolving threat landscape, leveraging advanced programming techniques to maintain stealth and maximize data capture. Organizations should monitor for unusual service activity, unexpected DLL injections, and persistent logging patterns to mitigate this threat.
Tags
Date
- Created: Sept. 1, 2025, 9:54 a.m.
- Published: Sept. 1, 2025, 9:54 a.m.
- Modified: Sept. 1, 2025, 10:33 a.m.
Indicators
- fe6a696e7012696f2e94a4d31b2f076f32c71d44e4c3cec69a6984ef0b81838a
- eb6752e60170199e4ce4d5de72fb539f807332771e1a668865aac1eee2c01d93
- 7834a64c39f85db5f073d76ddb453c5e23ad18244722d6853986934b750259fd